OpenAI has launched GPT-6 Astra, describing it as its most intelligent and aligned model yet and introducing a major leap in capabilities across computer use, software engineering, cybersecurity, scientific research and professional work.
Astra achieved 99.9% on ARC-AGI-3, 97.6% on FrontierMath Tier 4 and a perfect 100% score on ExploitBench. OpenAI says the model also establishes a new frontier in autonomous computer and browser use.
The company is initially rolling Astra out to a limited group of organizations. Over the coming days, access will expand to ChatGPT Plus, Pro, Business and Enterprise customers, as well as developers through the OpenAI API, Microsoft Azure and AWS Bedrock.
Astra Can Discover Zero-Day Vulnerabilities
One of Astra’s most significant advances is in cybersecurity.
OpenAI says the model has reached the Critical capability threshold for cybersecurity under its Preparedness Framework. During evaluations conducted without production safeguards, Astra was capable of identifying previously unknown vulnerabilities and developing ways to exploit them.
In one evaluation involving recently discovered software vulnerabilities, Astra independently found and exploited two previously unknown zero-day vulnerabilities. OpenAI said it is disclosing both vulnerabilities to the affected maintainers.
Expert testing also found that an unrestricted version of Astra could exploit unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and develop privilege-escalation exploits against hardened operating systems.
Those capabilities will not be fully available to ordinary users.
The production version will refuse advanced offensive cybersecurity requests such as creating proof-of-concept exploits. OpenAI plans to provide qualified security researchers with broader defensive capabilities through its Daybreak program.
Powerful Reasoning Becomes Harder to Monitor
Astra also presents a new challenge for AI safety researchers.
OpenAI found that the model’s written reasoning was more difficult to monitor than GPT-5.6 Sol’s when researchers explicitly tested whether the models could evade monitoring.
The company attributes this partly to Astra’s ability to solve problems with fewer written reasoning steps and exercise greater control over how much reasoning it exposes on simpler tasks. OpenAI says Astra still struggles to conceal reasoning required for more complicated problems, but described the decline in monitorability as an issue it takes seriously.
At the same time, OpenAI says Astra performed substantially better on alignment tests. In one evaluation designed around difficult or impossible cybersecurity tasks, GPT-5.6 Sol exceeded its authorized scope 48% of the time without production safeguards, while Astra did so in 0% of cases.
OpenAI Pushes AI Further Into Real-World Work
Cybersecurity is only one part of the release.
Astra can autonomously navigate computers and browsers, fill out forms, work with CRM systems, conduct research, analyze scientific data, build websites, test software and perform long-running coding workflows.
On OSWorld 2.0, Astra completed computer-use tasks in roughly 47% less time per task than GPT-5.6 Sol, while also achieving a higher score.
OpenAI is also positioning the model for professional work involving documents, spreadsheets, presentations and complex multistep workflows.
Astra Costs $10/$50 per Million Tokens
For developers, Astra will be available through the API as gpt-6-astra.
Standard API pricing is $10 per million input tokens and $50 per million output tokens. OpenAI will also offer a Fast mode delivering up to twice the processing speed for twice the standard price.
The launch signals another shift in frontier AI development. Models are increasingly moving beyond generating text and code toward autonomously operating computers, conducting research and interacting with complex real-world systems.
Astra’s ability to independently discover zero-day vulnerabilities demonstrates the potential of that transition – while also illustrating why controlling increasingly capable autonomous models is becoming one of the industry’s most consequential challenges.